yutori-computer-use
Warn
Audited by Socket on Sep 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's purpose and capabilities largely align, and the Yutori package path appears official, but it grants very powerful desktop permissions, forwards a stored API key to CLI tooling, and relies on a separate third-party driver for core functionality. This looks like a legitimate but high-impact computer-use skill with notable supply-chain and autonomy risk rather than confirmed malware.
Confidence: 85%Severity: 74%
Audit Metadata